VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 3 of 23
  • CVE-2023-31747HigMay 23, 2023
    risk 0.54cvss 7.8epss 0.01

    Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers to launch processes with elevated privileges.

  • CVE-2022-37197HigNov 18, 2022
    risk 0.54cvss 7.8epss 0.01

    IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.

  • CVE-2022-35899HigJul 21, 2022
    risk 0.54cvss 7.8epss 0.01

    There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.

  • CVE-2022-23909HigApr 5, 2022
    risk 0.54cvss 7.8epss 0.01

    There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.

  • CVE-2020-14521HigFeb 11, 2022
    risk 0.54cvss 8.3epss 0.01

    Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.

  • CVE-2019-18915HigFeb 13, 2020
    risk 0.54cvss 7.8epss 0.01

    A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system service.

  • CVE-2018-10619HigJun 7, 2018
    risk 0.54cvss 7.8epss 0.03

    An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the…

  • CVE-2024-34010HigApr 29, 2024
    risk 0.53cvss 8.2epss 0.00

    Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758, Acronis Cyber Protect 16 (Windows) before build 38690, Acronis True Image (Windows) before build 42386,…

  • CVE-2021-45460HigJan 11, 2022
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of…

  • CVE-2025-71326HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious…

  • CVE-2023-54353HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like…

  • CVE-2022-50971HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute…

  • CVE-2021-47985HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges…

  • CVE-2020-37254HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart…

  • CVE-2020-37253HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the…

  • CVE-2020-37252HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute…

  • CVE-2020-37251HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem…

  • CVE-2020-37250HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can place a malicious executable in the Program Files directory path that will be…

  • CVE-2019-25747HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration…

  • CVE-2016-20095HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the…